![]() |
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Hot Topics For discussion on main news stories hitting the headlines. |
|
|
Thread Tools |
|
|
#1 |
|
Lead Administrator
Owner ![]() Join Date: Oct 1990
Posts: 5,270
Thanks: 36
Thanked 312 Times in 112 Posts
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Warning on stealthy Windows virus
Warning on stealthy Windows virus
The creators of the virus are after bank logins and personal dataSecurity experts are warning about a stealthy Windows virus that steals login details for online bank accounts. In the last month, the malicious program has racked up about 5,000 victims - most of whom are in Europe. Many are falling victim via booby-trapped websites that use vulnerabilities in Microsoft's browser to install the attack code. Experts say the virus is dangerous because it buries itself deep inside Windows to avoid detection. Old tricks The malicious program is a type of virus known as a rootkit and it tries to overwrite part of a computer's hard drive called the Master Boot Record (MBR). This is where a computer looks when it is switched on for information about the operating system it will be running. "If you can control the MBR, you can control the operating system and therefore the computer it resides on," wrote Elia Florio on security company Symantec's blog. Mr Florio pointed out that many viruses dating from the days before Windows used the Master Boot Record to get a grip on a computer. Once installed the virus, dubbed Mebroot by Symantec, usually downloads other malicious programs, such as keyloggers, to do the work of stealing confidential information. Most of these associated programs lie in wait on a machine until its owner logs in to the online banking systems of one of more than 900 financial institutions. The Russian virus-writing group behind Mebroot is thought to have created the torpig family of viruses that are known to have been installed on more than 200,000 systems. This group specialises in stealing bank login information. Security firm iDefense said Mebroot was discovered in October but started to be used in a series of attacks in early December. Between 12 December and 7 January, iDefense detected more than 5,000 machines that had been infected with the program. Analysis of Mebroot has shown that it uses its hidden position on the MBR as a beachhead so it can re-install these associated programs if they are deleted by anti-virus software. Although the password-stealing programs that Mebroot installs can be found by security software, few commercial anti-virus packages currently detect its presence. Mebroot cannot be removed while a computer is running. Independent security firm GMER has produced a utility that will scan and remove the stealthy program. Computers running Windows XP, Windows Vista, Windows Server 2003 and Windows 2000 that are not fully patched are all vulnerable to the virus. |
|
|
|
|
|
#2 |
|
♥Yr Mangled Heart♥
![]() ![]() Join Date: Mar 2006
Shard: Black Water Raiders
Posts: 8,467
Thanks: 125
Thanked 33 Times in 24 Posts
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Re: Warning on stealthy Windows virus
Is this going to be a website or email i have to worry about?
![]()
__________________
![]() "Two Minutes in Heaven is Better then One Minute in Heaven." I'm not wearing my business socks for nothing
|
|
|
|
|
|
#3 |
|
Polar Bear Queen
![]() Join Date: Nov 2006
Shard: Atlantic & Lake Austin
Posts: 4,026
Thanks: 4
Thanked 5 Times in 5 Posts
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Re: Warning on stealthy Windows virus
I <3 my Mac
![]()
__________________
[UOCraft.com] - [Photography: Blog - Photo Gallery - Flickr] - [Other Blogs: Bird Blog - Geek Blog] |
|
|
|
|
|
#4 | |||
|
Lead Administrator
![]() ![]() Join Date: Mar 2005
Shard: Sonoma
Posts: 2,867
Blog Entries: 17
Thanks: 65
Thanked 173 Times in 59 Posts
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Re: Warning on stealthy Windows virus
Quote:
Quote:
and real important thing to do to protect ourselves ... Quote:
|
|||
|
|
|
|
|
#5 |
|
♥Yr Mangled Heart♥
![]() ![]() Join Date: Mar 2006
Shard: Black Water Raiders
Posts: 8,467
Thanks: 125
Thanked 33 Times in 24 Posts
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Re: Warning on stealthy Windows virus
Oh I missed that Mum! Thanks!
__________________
![]() "Two Minutes in Heaven is Better then One Minute in Heaven." I'm not wearing my business socks for nothing
|
|
|
|
|
|
#6 |
|
Madien of the Great Blue
Join Date: Jun 2006
Shard: City of Heroes - Virtue Shard
Posts: 1,903
Thanks: 3
Thanked 3 Times in 3 Posts
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Re: Warning on stealthy Windows virus
Always some ejets out there out there to give people a really bad day >_<
-RMS Carpathia-
__________________
|
|
|
|
|
|
#7 |
|
Mith'quessir
![]() ![]() Join Date: Mar 2005
Shard: Chesepeake
Posts: 2,081
Blog Entries: 3
Thanks: 72
Thanked 55 Times in 31 Posts
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Re: Warning on stealthy Windows virus
BitDefender has a 1 year free program, which also scans for webroots. They also offer a free online scan and clean.
I'm beginiing to like this program. Just an FYI.
__________________
![]() "Careful what you wish for, You just might get it all.... And then some you don't want" |
|
|
|
|
|
#8 |
|
Administrator
![]() ![]() Join Date: Mar 2006
Shard: Europa/Snowbourn
Posts: 5,543
Blog Entries: 3
Thanks: 86
Thanked 76 Times in 34 Posts
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Re: Warning on stealthy Windows virus
Oooooooh I had a new comp for christmas with Win Vista.What do I have to do to not get this virus *looks scared*
__________________
![]() |
|
|
|
|
|
#9 |
|
Whispering Rose Radio
Join Date: Mar 2007
Posts: 43
Thanks: 0
Thanked 0 Times in 0 Posts
![]() |
Re: Warning on stealthy Windows virus
what about firefox users? are we still as vulnerable?
__________________
![]() ![]() Help my egg hatch. Go to http://dragcave.ath.cx/user/36548 to help my other eggs! |
|
|
|
![]() |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| WARNING!!! Hackers sending out phishing attempts for accounts!!! WARNING!!! | Tabbitha | News & Developer's posts | 1 | 5th September 2007 09:23 AM |
| Virus question | Crypt Keeper(CK) | The Mausoleum | 5 | 4th August 2007 04:04 PM |
| Warning Fake UO site with Trojan Virus | Jirel of Joiry | Ultima Online General Discussion | 15 | 5th April 2007 04:50 PM |
| Virus Warning | Vepl | Jokes & Stuff | 6 | 19th March 2007 12:36 PM |
| Stealthy Devs Move in on Scripters | Thradia | News & Developer's posts | 25 | 26th March 2006 04:42 AM |